Network Asset Analysis System for Threat Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing network infrastructure data from disparate sources are inefficient, requiring manual querying and data aggregation, which hinders the identification of network threats and collaboration among analysts.

Innovation Solution

A network analysis system that enables the management of data about network assets in logical groups (projects) for analysis, allowing for the merging and connection of related assets and activities, and providing graphical interfaces for project management and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual querying and data aggregation from disparate sources is performed, then network threat identification is possible, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvenetwork threat identificationVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple disparate data sources (DNS, WHOIS, SSL, malware databases, etc.) into a unified network infrastructure analysis system. The system merges data from numerous external providers and internal sources into a single integrated platform, allowing analysts to query all sources simultaneously rather than manually visiting each source individually.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary processing layer that automatically retrieves, normalizes, and aggregates data from multiple external data sources. This intermediary system handles the complex task of querying numerous providers and transforming their diverse data formats into a unified structure, eliminating the need for manual data collection while maintaining comprehensive threat detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If individual data sources are queried manually, then specific network artifacts can be obtained, but operational complexity and difficulty of analysis increase

Engineering Contradiction:
Improvenetwork artifact retrievalVSAvoidoperational complexity
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent creates a universal query interface that can retrieve all types of network artifacts (DNS records, WHOIS data, SSL certificates, malware indicators, etc.) through a single standardized mechanism. This multi-functional system handles diverse data types and sources uniformly, allowing analysts to obtain any network artifact through the same simple query process regardless of the underlying data source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the complex data retrieval process into distinct modular components: data collection modules for each source type, normalization modules for transforming diverse formats, and presentation modules for displaying artifacts. This segmentation allows the system to manage complexity internally while presenting a simplified interface to users.

Inventive Principle:
Principle #1Segmentation

3Reliability

If data from multiple sources is aggregated manually, then comprehensive network analysis is possible, but device complexity and system resource requirements increase

Engineering Contradiction:
Improvecomprehensive network analysisVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested architecture where multiple data source interfaces are nested within a unified data aggregation layer, which is in turn nested within the analysis platform. Each external data source is accessed through its own nested interface module, which handles source-specific protocols and formats, while presenting a standardized interface to the upper layers. This nesting allows comprehensive multi-source analysis while encapsulating complexity within discrete, manageable modules.

Inventive Principle:
Principle #7Nested doll (Nesting)

4Quantity of substance

If network activity monitoring is performed without visualization tools, then data collection is possible, but pattern recognition and trend identification become difficult

Engineering Contradiction:
Improvenetwork data collectionVSAvoidpattern recognition
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent employs visual encoding where different network activities, threat levels, and artifact types are represented by distinct colors and visual indicators. Network events are color-coded to indicate their nature and severity, allowing analysts to quickly recognize patterns and anomalies through visual scanning rather than analyzing raw data text. This visual representation transforms large volumes of network data into easily interpretable graphical displays.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS12273361B2Techniques for managing projects and monitoring network-based assets
Publication Date: 2025.04.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12273361B2 patent drawing
  • US12273361B2 patent drawing
  • US12273361B2 patent drawing

AI summary

Techniques are disclosed of enabling projects to be managed for grouping artifacts about related network activity. A graphical interface can be provided to enable users to create both public and private projects with information including names, descriptions, collaborators and monitoring profiles. A project can include context and history of the project so multiple users can collaborate within a project to view the analysis process as assets are identified in the project. Information is retrieved for identified assets in separate projects and is available for display in the graphical interface.